1

Vulnerability Management Jobs in Remote, OR (NOW HIRING)

Coordinate vulnerability management activities, including intake, triage, risk assessment, remediation tracking, and documentation of product security issues through closure. * Serve as the Surgical ...

Support audits, vulnerability management, patching, and risk remediation. Team & Organizational Leadership * Leads cloud operations through transformation, including the transition from traditional ...

Support audits, vulnerability management, patching, and risk remediation. Team & Organizational Leadership * Leads cloud operations through transformation, including the transition from traditional ...

Oversee threat intelligence, vulnerability management, and incident response with a focus on automation and continuous improvement. * Partner with CloudOps and DevOps teams to integrate DevSecOps ...

Oversee threat intelligence, vulnerability management, and incident response with a focus on automation and continuous improvement. * Partner with CloudOps and DevOps teams to integrate DevSecOps ...

DevOps Developer

OR · On-site +1

Support vulnerability scanning, dependency checks, container image scanning, secrets management, and policy enforcement. * Collaborate with Security and Architecture teams to improve secure software ...

Support vulnerability scanning, dependency checks, container image scanning, secrets management, and policy enforcement. * Collaborate with Security and Architecture teams to improve secure software ...

Vulnerability Management information

What is vulnerability management?

A Vulnerability Management job involves identifying, assessing, prioritizing, and mitigating security vulnerabilities in an organization's systems, networks, and applications. Professionals in this role use tools like vulnerability scanners and threat intelligence to detect weaknesses and coordinate remediation efforts with IT and security teams. They also establish policies, monitor security risks, and ensure compliance with industry standards. The goal is to reduce the organization's exposure to cyber threats and improve overall security posture.

What are the common challenges faced in a vulnerability management role?

Professionals in Vulnerability Management often encounter challenges such as rapidly evolving threat landscapes, prioritizing remediation efforts among numerous vulnerabilities, and ensuring continuous communication between technical and non-technical stakeholders. They may also need to adapt to changing regulatory requirements and work within tight deadlines to protect the organization from emerging risks. As part of this role, you'll collaborate regularly with IT, security, and business teams to ensure remediation steps are effectively implemented. Continuous learning and adaptability are important, as technologies and attack vectors change frequently in this field. Being proactive and detail-oriented will help you address these challenges and advance your career in cybersecurity.

What are the key skills and qualifications needed to thrive in a vulnerability management position?

To thrive in Vulnerability Management, you need a strong understanding of cybersecurity principles, network protocols, and risk assessment, typically supported by a relevant degree and experience in information security. Familiarity with vulnerability scanning tools (such as Nessus or Qualys), security frameworks, and industry certifications like CISSP or CompTIA Security+ is highly valued. Exceptional analytical thinking, communication skills, and an ability to work collaboratively across IT and business teams help professionals excel in this field. These competencies are crucial to effectively identifying, prioritizing, and mitigating security risks in dynamic organizational environments.

Is vulnerability management a good career?

Vulnerability management is a valuable cybersecurity role focused on identifying and mitigating security weaknesses in systems. It requires knowledge of security tools, risk assessment, and often certifications like CISSP or CompTIA Security+; the field offers strong job growth and competitive salaries. It is suitable for individuals interested in technical problem-solving and continuous learning in cybersecurity.

What does a vulnerability management do?

A vulnerability management professional is responsible for identifying, assessing, and prioritizing security vulnerabilities in an organization’s systems and networks. They use tools like vulnerability scanners and follow best practices to mitigate risks, often working closely with security teams and maintaining documentation for compliance. This role requires technical knowledge of cybersecurity principles and may involve certifications such as CISSP or CompTIA Security+.

What are the most commonly searched types of Vulnerability Management jobs in Remote, OR?

The most popular types of Vulnerability Management jobs in Remote, OR are:

What are popular job titles related to Vulnerability Management jobs in Remote, OR?

For Vulnerability Management jobs in Remote, OR, the most frequently searched job titles are:

What job categories do people searching Vulnerability Management jobs in Remote, OR look for?

The top searched job categories for Vulnerability Management jobs in Remote, OR are:

What cities near Remote, OR are hiring for Vulnerability Management jobs?

Cities near Remote, OR with the most Vulnerability Management job openings:

Infographic showing various Vulnerability Management job openings in Remote, OR as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 12% Part Time, and 3% Contract. Highlights an 71% Physical, 3% Hybrid, and 26% Remote job distribution.

Product Cybersecurity Architect

Bausch + Lomb

OR • On-site, Remote

Full-time

Dental, Vision, Life, Retirement, PTO

Re-posted 8 days ago


Bausch & Lomb rating

8.6

Company rating: 8.6 out of 10

Based on 39 frontline employees who took The Breakroom Quiz

21st of 540 rated manufacturers


Job description

Bausch + Lomb (NYSE/TSX: BLCO) is a leading global eye health company dedicated to protecting and enhancing the gift of sight for millions of people around the world-from the moment of birth through every phase of life. Our mission is simple, yet powerful: helping you see better, to live better.
Our comprehensive portfolio of over 400 products is fully integrated and built to serve our customers across the full spectrum of their eye health needs throughout their lives. Our iconic brand is built on the deep trust and loyalty of our customers established over our 170-year history. We have a significant global research, development, manufacturing and commercial footprint of approximately 13,000 employees and a presence in approximately 100 countries, extending our reach to billions of potential customers across the globe. We have long been associated with many of the most significant advances in eye health, and we believe we are well positioned to continue leading the advancement of eye health in the future.
Why this Role Matters
Join the Surgical R&D organization in a role where you will help ensure the cybersecurity, safety, and reliability of innovative surgical products that support patient care. In this position, you will be responsible for embedding secure-by-design practices throughout the product lifecycle while partnering with engineering, quality, regulatory, and corporate security teams to deliver compliant and resilient solutions. This is a strong opportunity for someone who brings deep product security expertise, strong cross-functional collaboration skills, and a passion for advancing cybersecurity within a regulated medical device environment.
What You'll Do
  • Architect and implement a consistent cybersecurity strategy across surgical capital equipment product lines to establish a scalable and secure product ecosystem.
  • Embed secure-by-design principles throughout the product lifecycle, providing guidance on secure architecture, threat modeling, design controls, cryptography, and secure communication protocols.
  • Lead execution of cybersecurity requirements across development programs, ensuring alignment with regulatory expectations, corporate standards, and product quality objectives.
  • Coordinate vulnerability management activities, including intake, triage, risk assessment, remediation tracking, and documentation of product security issues through closure.
  • Serve as the Surgical R&D cybersecurity representative for vulnerability disclosure and incident response activities, supporting investigations, impact assessments, root cause analyses, and remediation efforts.
  • Partner with engineering teams to implement security testing practices, including SAST, DAST, SCA, penetration testing, and automated security controls within development pipelines.
  • Support supplier and third-party security initiatives by defining security requirements, managing software supply chain risks, and maintaining Software Bill of Materials (SBOM) processes.
  • Collaborate with Quality, Regulatory Affairs, IT, and Corporate Product Security teams to ensure compliance with evolving cybersecurity regulations and industry standards while enabling efficient product delivery.

What You'll Bring
Required Education & Experience:
  • Bachelor's degree in Engineering, Computer Science, Cybersecurity, or a related technical discipline.
  • 7+ years of experience in product security, application security, medical device cybersecurity, or software security within a regulated environment.
  • Demonstrated experience supporting or leading cybersecurity activities for medical device or other regulated product development programs.
  • Strong communication, collaboration, stakeholder management, and problem-solving skills.
  • Ability to translate technical cybersecurity risks into clear, actionable guidance for engineering, quality, and regulatory stakeholders.

Specialized Technical, Regulatory & Industry Skills & Knowledge
  • Strong expertise in secure product design, threat modeling, vulnerability management, and secure software development practices.
  • Working knowledge of connected device security, embedded systems, and software-enabled product architectures.
  • Experience with security testing tools and methodologies, including SAST, DAST, SCA, and penetration testing.
  • Understanding of software supply chain security practices, including SBOM development and third-party risk management.
  • Experience working across cross-functional and global teams to drive cybersecurity outcomes and influence stakeholders without direct authority.
  • Knowledge of secure development lifecycle (SDLC) frameworks, vulnerability disclosure processes, and product incident response activities.
  • Familiarity with cybersecurity governance, risk assessment, and compliance processes within regulated industries.

Preferred
  • Advanced degree in Cybersecurity, Computer Science, Engineering, or a related field.
  • Relevant industry certifications such as CISSP, CSSLP, OSCP, GWAPT, or equivalent.
  • Experience in medical device, healthcare, or other regulated industries, and/or working within a quality-managed or GxP regulated environment.
  • Working knowledge of medical device cybersecurity regulations and standards (e.g., FDA premarket/post market guidance, IEC 81001-5-1, AAMI TIR57, UL 2900, NIST frameworks).
  • Experience developing cybersecurity documentation to support regulatory submissions and audits.

This position may be available in the following location(s): US - Remote
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
For U.S. locations that require disclosure of compensation, the starting pay for this role is between $140,000 and $180,000. The estimated salary range reflects an anticipated range for this position. The actual base salary offered may depend on a variety of factors.
U.S. based employees may be eligible for short-term and/or long-term incentives. They may also be eligible to participate in medical, dental, vision insurance, disability and life insurance, a 401(k) plan and company match, a tuition reimbursement program (select degrees), company holidays, and well-being benefits, among others. U.S. based employees are also eligible to receive sick time, floating holidays and paid vacation.
Job Applicants should be aware of job offer scams perpetrated through the use of the Internet and social media platforms.
To learn more please read Bausch + Lomb's Job Offer Fraud Statement.
Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.

What Bausch & Lomb employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Bausch & Lomb logo

About Bausch & Lomb

Sourced by ZipRecruiter

Bausch + Lomb (NYSE/TSX: BLCO) is a leading global eye health company dedicated to protecting and enhancing the gift of sight for millions of people around the world--from the moment of birth through every phase of life. Our mission is simple, yet powerful: helping you see better, to live better. Our comprehensive portfolio of over 400 products is fully integrated and built to serve our customers across the full spectrum of their eye health needs throughout their lives. Our iconic brand is built on the deep trust and loyalty of our customers established over our nearly 170-year history. We have a significant global research, development, manufacturing and commercial footprint of approximately 12,500 employees and a presence in approximately 100 countries, extending our reach to billions of potential customers across the globe. We have long been associated with many of the most significant advances in eye health, and we believe we are well positioned to continue leading the advancement of eye health in the future.

Industry

Medical equipment and supplies manufacturing

Company size

10,000+ Employees

Headquarters location

Bridgewater, NJ, US

Year founded

1853